Skip to content

feat(memory): add verified native backup and explicit remap restore - #252

Merged
replygirl merged 8 commits into
mainfrom
feat/restorable-memory-backup-delivery
Oct 7, 2026
Merged

replygirl merged 8 commits into
mainfrom
feat/restorable-memory-backup-delivery

Conversation

@replygirl

@replygirl replygirl commented Oct 7, 2026 •

Copy link
Copy Markdown
Owner

Memory backup captures a complete native image and provenance for independent offline verification. Absent-target restore validates the graph and working roots, requires explicit project remap, preserves conversations and private summaries, and reconstructs fresh service authority before retained-session resume.

Validation: Actual CLI backup/verify/remap/restore/resume, two writers, lost publication, corrupt image, caller-drop, dirty remap, ready-stage private-summary recovery and historical/protocol fixtures passed. Host/Windows static checks, docs and strict/managed validation passed; the feature and its integration corrections are archived. Native supported-platform CI and the unchanged workspace coverage gate remain required; local barriers do not claim literal byte-copy overlap.

CI caught three integration contracts: an exact hello baseline omitted declared protocol 1.13 history_scope:null; the staged restore commit used a short message alias forbidden by the strict branch-operation scanner; and the preferences fixture expected foreign-project access through a store bound to another project. The hello baseline now includes the declared field, staged commits use the established --message alias, and the preferences fixture proves refusal before checking defaults through a separately bound store. Both stores are explicitly closed at their proper lifecycle boundaries. Production serialization, project authority, scanner rules and all original restore/preferences assertions remain intact.

Focused validation: starter-token and pinned protocol-surface checks 2/2; both existing branch-scanner cases plus dirty remapped restore 3/3; corrected preferences case 1/1 and existing closing guard passed. The initial preferences check exposed an intermediate universal-close helper misuse; direct close of the other store corrected it, while final universal cleanup proof remains. Relevant host/Windows lint, typecheck, formatting, docs, managed checks and normal hooks passed. Fresh final-head full CI and exact-main acceptance are required before delivery closure.

Native Windows CI then exposed a second live stage-root handle during checked validation-stage removal. ImageStage now drops its original handle and consumes the existing lifecycle seal through its checked removal API, retaining the lifecycle lock and exact identity checks. No platform absence rule, worker ownership, maintenance authority, deadline or fixture assertion changed. Unchanged historical dirty restore and the existing backup closing guard passed 2/2 locally; affected host/Windows lint, typecheck, docs, format and managed/strict checks passed, and the fix is archived. On cb7cacb, native Windows x64 prepared backup, historical dirty restore, CLI remap/resume, EOF/lost-reply settlement and managed writer/captured-cut cases passed in their actual selected jobs. Full corrected-head CI and exact-main acceptance remain required.

The corruption fixture then exposed retained stats repositories one level beyond its default scan. Only that root now names depth ten through the documented oldgen leaf; the global depth/entry guard, rejection beyond a named budget, all native validation and awaited-quiescence assertions are unchanged. The first named-nine CI still found the documented oldgen leaf at depth ten on both Windows architectures. The complete named-ten follow-up preserves the original archives; unchanged corruption, closing and named-depth guards passed3/3 locally with affected statics clear. Fresh final-head native execution is required.

Separately, old-updater acceptance passed its installation and identity assertions before root retirement failed OS32; the actual locker is unknown. Windows command output now aborts and awaits the same optional diagnostic sampler before returning either captured outcome, disposing its duplicate handle. Primary output/errors, owned Job cleanup, limits and deadlines are unchanged. Host/Windows lint and typecheck, format and managed checks passed; At da80320 native Windows x64 previous-release acceptance passed the actual v0.9.0 updater roundtrip and strict root retirement; ARM installation passed but had no published predecessor. The historical locker is still unproved. Both corrections are archived; fresh native previous-release acceptance and full CI must pass before merge.

macOS CI later found the read-only inspection fixture comparing the ephemeral live_presence_known boolean as durable state. It now requires boolean presence and null live_driver in both listings, removes only the presence boolean, and compares every remaining catalog/runtime field exactly. All no-provision, status/history/revision, provider and invalid-limit assertions remain. Exact real inspection and app closing guard passed1/1 each locally, along with host/Windows lint, typecheck, format and managed checks; the typed test record is archived. Both Windows corruption targets passed92/92 on the previous e8 head. Fresh final-head full CI remains required.

Copilot AI balanced review requested due to automatic review settings October 7, 2026 01:36

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@replygirl
replygirl merged commit 6950d5c into main Oct 7, 2026
70 checks passed
@replygirl
replygirl deleted the feat/restorable-memory-backup-delivery branch October 7, 2026 04:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants